self-learning
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose broadly matches its capabilities, but its core design is risky: it converts untrusted web content into persistent agent instructions and saves them as installable skills. That creates a high prompt-injection and transitive-trust risk even without obvious credential theft or malicious exfiltration.
Confidence: 91%Severity: 76%
Audit Metadata